←back to thread

1208 points jamesberthoty | 2 comments | | HN request time: 0.604s | source
1. m3kw9 ◴[] No.45264364[source]
Is using any type of NPM type stuff a no go? Who reads the code and verifies is secure?
replies(1): >>45267179 #
2. theruss ◴[] No.45267179[source]
Other than the maintainer (which isn't of course guaranteed) no-one other than it being incumbent on userland deployment, and those deploying a lib into a project to review the code.